redhatopenshift.azure.com/v20260901preview
APIVersion
| Value | Description |
|---|---|
| “2026-09-01-preview” |
HcpOpenShiftCluster
Generator information:
- Generated from: /redhatopenshift/resource-manager/Microsoft.RedHatOpenShift/hcpopenshiftclusters/preview/2026-09-01-preview/openapi.json
- ARM URI: /subscriptions/{subscriptionId}/resourceGroups/{resourceGroupName}/providers/Microsoft.RedHatOpenShift/hcpOpenShiftClusters/{hcpOpenShiftClusterName}
Used by: HcpOpenShiftClusterList.
| Property | Description | Type |
|---|---|---|
| metav1.TypeMeta | ||
| metav1.ObjectMeta | ||
| spec | HcpOpenShiftCluster_Spec Optional |
|
| status | HcpOpenShiftCluster_STATUS Optional |
HcpOpenShiftCluster_Spec
| Property | Description | Type |
|---|---|---|
| azureName | The name of the resource in Azure. This is often the same as the name of the resource in Kubernetes but it doesn’t have to be. | string Optional |
| identity | The managed service identities assigned to this resource. | ManagedServiceIdentity Optional |
| location | The geo-location where the resource lives | string Required |
| operatorSpec | The specification for configuring operator behavior. This field is interpreted by the operator and not passed directly to Azure | HcpOpenShiftClusterOperatorSpec Optional |
| owner | The owner of the resource. The owner controls where the resource goes when it is deployed. The owner also controls the resources lifecycle. When the owner is deleted the resource will also be deleted. Owner is expected to be a reference to a resources.azure.com/ResourceGroup resource | genruntime.KnownResourceReference Required |
| properties | The resource-specific properties for this resource. | HcpOpenShiftClusterProperties Optional |
| tags | Resource tags. | map[string]string Optional |
HcpOpenShiftCluster_STATUS
| Property | Description | Type |
|---|---|---|
| conditions | The observed state of the resource | conditions.Condition[] Optional |
| id | Fully qualified resource ID for the resource. E.g. “/subscriptions/{subscriptionId}/resourceGroups/{resourceGroupName}/providers/{resourceProviderNamespace}/{resourceType}/{resourceName}” | string Optional |
| identity | The managed service identities assigned to this resource. | ManagedServiceIdentity_STATUS Optional |
| location | The geo-location where the resource lives | string Optional |
| name | The name of the resource | string Optional |
| properties | The resource-specific properties for this resource. | HcpOpenShiftClusterProperties_STATUS Optional |
| systemData | Azure Resource Manager metadata containing createdBy and modifiedBy information. | SystemData_STATUS Optional |
| tags | Resource tags. | map[string]string Optional |
| type | The type of the resource. E.g. “Microsoft.Compute/virtualMachines” or “Microsoft.Storage/storageAccounts” | string Optional |
HcpOpenShiftClusterList
Generator information:
- Generated from: /redhatopenshift/resource-manager/Microsoft.RedHatOpenShift/hcpopenshiftclusters/preview/2026-09-01-preview/openapi.json
- ARM URI: /subscriptions/{subscriptionId}/resourceGroups/{resourceGroupName}/providers/Microsoft.RedHatOpenShift/hcpOpenShiftClusters/{hcpOpenShiftClusterName}
| Property | Description | Type |
|---|---|---|
| metav1.TypeMeta | ||
| metav1.ListMeta | ||
| items | HcpOpenShiftCluster[] Optional |
HcpOpenShiftClustersExternalAuth
Generator information:
- Generated from: /redhatopenshift/resource-manager/Microsoft.RedHatOpenShift/hcpopenshiftclusters/preview/2026-09-01-preview/openapi.json
- ARM URI: /subscriptions/{subscriptionId}/resourceGroups/{resourceGroupName}/providers/Microsoft.RedHatOpenShift/hcpOpenShiftClusters/{hcpOpenShiftClusterName}/externalAuths/{externalAuthName}
Used by: HcpOpenShiftClustersExternalAuthList.
| Property | Description | Type |
|---|---|---|
| metav1.TypeMeta | ||
| metav1.ObjectMeta | ||
| spec | HcpOpenShiftClustersExternalAuth_Spec Optional |
|
| status | HcpOpenShiftClustersExternalAuth_STATUS Optional |
HcpOpenShiftClustersExternalAuth_Spec
| Property | Description | Type |
|---|---|---|
| azureName | The name of the resource in Azure. This is often the same as the name of the resource in Kubernetes but it doesn’t have to be. | string Optional |
| operatorSpec | The specification for configuring operator behavior. This field is interpreted by the operator and not passed directly to Azure | HcpOpenShiftClustersExternalAuthOperatorSpec Optional |
| owner | The owner of the resource. The owner controls where the resource goes when it is deployed. The owner also controls the resources lifecycle. When the owner is deleted the resource will also be deleted. Owner is expected to be a reference to a redhatopenshift.azure.com/HcpOpenShiftCluster resource | genruntime.KnownResourceReference Required |
| properties | The resource-specific properties for this resource. | ExternalAuthProperties Optional |
HcpOpenShiftClustersExternalAuth_STATUS
| Property | Description | Type |
|---|---|---|
| conditions | The observed state of the resource | conditions.Condition[] Optional |
| id | Fully qualified resource ID for the resource. E.g. “/subscriptions/{subscriptionId}/resourceGroups/{resourceGroupName}/providers/{resourceProviderNamespace}/{resourceType}/{resourceName}” | string Optional |
| name | The name of the resource | string Optional |
| properties | The resource-specific properties for this resource. | ExternalAuthProperties_STATUS Optional |
| systemData | Azure Resource Manager metadata containing createdBy and modifiedBy information. | SystemData_STATUS Optional |
| type | The type of the resource. E.g. “Microsoft.Compute/virtualMachines” or “Microsoft.Storage/storageAccounts” | string Optional |
HcpOpenShiftClustersExternalAuthList
Generator information:
- Generated from: /redhatopenshift/resource-manager/Microsoft.RedHatOpenShift/hcpopenshiftclusters/preview/2026-09-01-preview/openapi.json
- ARM URI: /subscriptions/{subscriptionId}/resourceGroups/{resourceGroupName}/providers/Microsoft.RedHatOpenShift/hcpOpenShiftClusters/{hcpOpenShiftClusterName}/externalAuths/{externalAuthName}
| Property | Description | Type |
|---|---|---|
| metav1.TypeMeta | ||
| metav1.ListMeta | ||
| items | HcpOpenShiftClustersExternalAuth[] Optional |
HcpOpenShiftClustersNodePool
Generator information:
- Generated from: /redhatopenshift/resource-manager/Microsoft.RedHatOpenShift/hcpopenshiftclusters/preview/2026-09-01-preview/openapi.json
- ARM URI: /subscriptions/{subscriptionId}/resourceGroups/{resourceGroupName}/providers/Microsoft.RedHatOpenShift/hcpOpenShiftClusters/{hcpOpenShiftClusterName}/nodePools/{nodePoolName}
Used by: HcpOpenShiftClustersNodePoolList.
| Property | Description | Type |
|---|---|---|
| metav1.TypeMeta | ||
| metav1.ObjectMeta | ||
| spec | HcpOpenShiftClustersNodePool_Spec Optional |
|
| status | HcpOpenShiftClustersNodePool_STATUS Optional |
HcpOpenShiftClustersNodePool_Spec
| Property | Description | Type |
|---|---|---|
| azureName | The name of the resource in Azure. This is often the same as the name of the resource in Kubernetes but it doesn’t have to be. | string Optional |
| identity | The managed service identities assigned to this resource. | ManagedServiceIdentity Optional |
| location | The geo-location where the resource lives | string Required |
| operatorSpec | The specification for configuring operator behavior. This field is interpreted by the operator and not passed directly to Azure | HcpOpenShiftClustersNodePoolOperatorSpec Optional |
| owner | The owner of the resource. The owner controls where the resource goes when it is deployed. The owner also controls the resources lifecycle. When the owner is deleted the resource will also be deleted. Owner is expected to be a reference to a redhatopenshift.azure.com/HcpOpenShiftCluster resource | genruntime.KnownResourceReference Required |
| properties | The resource-specific properties for this resource. | NodePoolProperties Optional |
| tags | Resource tags. | map[string]string Optional |
HcpOpenShiftClustersNodePool_STATUS
| Property | Description | Type |
|---|---|---|
| conditions | The observed state of the resource | conditions.Condition[] Optional |
| id | Fully qualified resource ID for the resource. E.g. “/subscriptions/{subscriptionId}/resourceGroups/{resourceGroupName}/providers/{resourceProviderNamespace}/{resourceType}/{resourceName}” | string Optional |
| identity | The managed service identities assigned to this resource. | ManagedServiceIdentity_STATUS Optional |
| location | The geo-location where the resource lives | string Optional |
| name | The name of the resource | string Optional |
| properties | The resource-specific properties for this resource. | NodePoolProperties_STATUS Optional |
| systemData | Azure Resource Manager metadata containing createdBy and modifiedBy information. | SystemData_STATUS Optional |
| tags | Resource tags. | map[string]string Optional |
| type | The type of the resource. E.g. “Microsoft.Compute/virtualMachines” or “Microsoft.Storage/storageAccounts” | string Optional |
HcpOpenShiftClustersNodePoolList
Generator information:
- Generated from: /redhatopenshift/resource-manager/Microsoft.RedHatOpenShift/hcpopenshiftclusters/preview/2026-09-01-preview/openapi.json
- ARM URI: /subscriptions/{subscriptionId}/resourceGroups/{resourceGroupName}/providers/Microsoft.RedHatOpenShift/hcpOpenShiftClusters/{hcpOpenShiftClusterName}/nodePools/{nodePoolName}
| Property | Description | Type |
|---|---|---|
| metav1.TypeMeta | ||
| metav1.ListMeta | ||
| items | HcpOpenShiftClustersNodePool[] Optional |
HcpOpenShiftCluster_Spec
Used by: HcpOpenShiftCluster.
| Property | Description | Type |
|---|---|---|
| azureName | The name of the resource in Azure. This is often the same as the name of the resource in Kubernetes but it doesn’t have to be. | string Optional |
| identity | The managed service identities assigned to this resource. | ManagedServiceIdentity Optional |
| location | The geo-location where the resource lives | string Required |
| operatorSpec | The specification for configuring operator behavior. This field is interpreted by the operator and not passed directly to Azure | HcpOpenShiftClusterOperatorSpec Optional |
| owner | The owner of the resource. The owner controls where the resource goes when it is deployed. The owner also controls the resources lifecycle. When the owner is deleted the resource will also be deleted. Owner is expected to be a reference to a resources.azure.com/ResourceGroup resource | genruntime.KnownResourceReference Required |
| properties | The resource-specific properties for this resource. | HcpOpenShiftClusterProperties Optional |
| tags | Resource tags. | map[string]string Optional |
HcpOpenShiftCluster_STATUS
HCP cluster resource
Used by: HcpOpenShiftCluster.
| Property | Description | Type |
|---|---|---|
| conditions | The observed state of the resource | conditions.Condition[] Optional |
| id | Fully qualified resource ID for the resource. E.g. “/subscriptions/{subscriptionId}/resourceGroups/{resourceGroupName}/providers/{resourceProviderNamespace}/{resourceType}/{resourceName}” | string Optional |
| identity | The managed service identities assigned to this resource. | ManagedServiceIdentity_STATUS Optional |
| location | The geo-location where the resource lives | string Optional |
| name | The name of the resource | string Optional |
| properties | The resource-specific properties for this resource. | HcpOpenShiftClusterProperties_STATUS Optional |
| systemData | Azure Resource Manager metadata containing createdBy and modifiedBy information. | SystemData_STATUS Optional |
| tags | Resource tags. | map[string]string Optional |
| type | The type of the resource. E.g. “Microsoft.Compute/virtualMachines” or “Microsoft.Storage/storageAccounts” | string Optional |
HcpOpenShiftClustersExternalAuth_Spec
Used by: HcpOpenShiftClustersExternalAuth.
| Property | Description | Type |
|---|---|---|
| azureName | The name of the resource in Azure. This is often the same as the name of the resource in Kubernetes but it doesn’t have to be. | string Optional |
| operatorSpec | The specification for configuring operator behavior. This field is interpreted by the operator and not passed directly to Azure | HcpOpenShiftClustersExternalAuthOperatorSpec Optional |
| owner | The owner of the resource. The owner controls where the resource goes when it is deployed. The owner also controls the resources lifecycle. When the owner is deleted the resource will also be deleted. Owner is expected to be a reference to a redhatopenshift.azure.com/HcpOpenShiftCluster resource | genruntime.KnownResourceReference Required |
| properties | The resource-specific properties for this resource. | ExternalAuthProperties Optional |
HcpOpenShiftClustersExternalAuth_STATUS
Used by: HcpOpenShiftClustersExternalAuth.
| Property | Description | Type |
|---|---|---|
| conditions | The observed state of the resource | conditions.Condition[] Optional |
| id | Fully qualified resource ID for the resource. E.g. “/subscriptions/{subscriptionId}/resourceGroups/{resourceGroupName}/providers/{resourceProviderNamespace}/{resourceType}/{resourceName}” | string Optional |
| name | The name of the resource | string Optional |
| properties | The resource-specific properties for this resource. | ExternalAuthProperties_STATUS Optional |
| systemData | Azure Resource Manager metadata containing createdBy and modifiedBy information. | SystemData_STATUS Optional |
| type | The type of the resource. E.g. “Microsoft.Compute/virtualMachines” or “Microsoft.Storage/storageAccounts” | string Optional |
HcpOpenShiftClustersNodePool_Spec
Used by: HcpOpenShiftClustersNodePool.
| Property | Description | Type |
|---|---|---|
| azureName | The name of the resource in Azure. This is often the same as the name of the resource in Kubernetes but it doesn’t have to be. | string Optional |
| identity | The managed service identities assigned to this resource. | ManagedServiceIdentity Optional |
| location | The geo-location where the resource lives | string Required |
| operatorSpec | The specification for configuring operator behavior. This field is interpreted by the operator and not passed directly to Azure | HcpOpenShiftClustersNodePoolOperatorSpec Optional |
| owner | The owner of the resource. The owner controls where the resource goes when it is deployed. The owner also controls the resources lifecycle. When the owner is deleted the resource will also be deleted. Owner is expected to be a reference to a redhatopenshift.azure.com/HcpOpenShiftCluster resource | genruntime.KnownResourceReference Required |
| properties | The resource-specific properties for this resource. | NodePoolProperties Optional |
| tags | Resource tags. | map[string]string Optional |
HcpOpenShiftClustersNodePool_STATUS
Used by: HcpOpenShiftClustersNodePool.
| Property | Description | Type |
|---|---|---|
| conditions | The observed state of the resource | conditions.Condition[] Optional |
| id | Fully qualified resource ID for the resource. E.g. “/subscriptions/{subscriptionId}/resourceGroups/{resourceGroupName}/providers/{resourceProviderNamespace}/{resourceType}/{resourceName}” | string Optional |
| identity | The managed service identities assigned to this resource. | ManagedServiceIdentity_STATUS Optional |
| location | The geo-location where the resource lives | string Optional |
| name | The name of the resource | string Optional |
| properties | The resource-specific properties for this resource. | NodePoolProperties_STATUS Optional |
| systemData | Azure Resource Manager metadata containing createdBy and modifiedBy information. | SystemData_STATUS Optional |
| tags | Resource tags. | map[string]string Optional |
| type | The type of the resource. E.g. “Microsoft.Compute/virtualMachines” or “Microsoft.Storage/storageAccounts” | string Optional |
ExternalAuthProperties
External Auth profile
Used by: HcpOpenShiftClustersExternalAuth_Spec.
| Property | Description | Type |
|---|---|---|
| claim | External Auth claim This configures how claims are validated and applied. | ExternalAuthClaimProfile Required |
| clients | External Auth OIDC clients There must not be more than 20 entries and entries must have unique namespace/name pairs. | ExternalAuthClientProfile[] Optional |
| issuer | Token Issuer profile | TokenIssuerProfile Required |
ExternalAuthProperties_STATUS
External Auth profile
Used by: HcpOpenShiftClustersExternalAuth_STATUS.
| Property | Description | Type |
|---|---|---|
| claim | External Auth claim This configures how claims are validated and applied. | ExternalAuthClaimProfile_STATUS Optional |
| clients | External Auth OIDC clients There must not be more than 20 entries and entries must have unique namespace/name pairs. | ExternalAuthClientProfile_STATUS[] Optional |
| issuer | Token Issuer profile | TokenIssuerProfile_STATUS Optional |
| provisioningState | Provisioning state | ExternalAuthProvisioningState_STATUS Optional |
| status | Status of the external auth resource | ResourceStatus_STATUS Optional |
HcpOpenShiftClusterOperatorSpec
Details for configuring operator behavior. Fields in this struct are interpreted by the operator directly rather than being passed to Azure
Used by: HcpOpenShiftCluster_Spec.
| Property | Description | Type |
|---|---|---|
| configMapExpressions | configures where to place operator written dynamic ConfigMaps (created with CEL expressions). | core.DestinationExpression[] Optional |
| secretExpressions | configures where to place operator written dynamic secrets (created with CEL expressions). | core.DestinationExpression[] Optional |
| secrets | configures where to place Azure generated secrets. | HcpOpenShiftClusterOperatorSecrets Optional |
HcpOpenShiftClusterProperties
HCP cluster properties
Used by: HcpOpenShiftCluster_Spec.
| Property | Description | Type |
|---|---|---|
| api | Shows the cluster API server profile | ApiProfile Optional |
| autoscaling | Configure ClusterAutoscaling . | ClusterAutoscalingProfile Optional |
| clusterImageRegistry | OpenShift internal image registry | ClusterImageRegistryProfile Optional |
| cryptoRestrictions | Cryptographic restrictions for kernel and userspace libraries | HcpOpenShiftClusterProperties_CryptoRestrictions Optional |
| dns | Cluster DNS configuration | DnsProfile Optional |
| etcd | Configure ETCD. | EtcdProfile Optional |
| imageDigestMirrors | imageDigestMirrors is a set of rules to allow pulling images from a mirrored registry by using digest specifications. WARNING: Updating this array will redeploy all node pools in the cluster. | ImageDigestMirror[] Optional |
| ingress | The cluster ingress configuration | IngressProfile Optional |
| network | Cluster network configuration | NetworkProfile Optional |
| nodeDrainTimeoutMinutes | nodeDrainTimeoutMinutes is the grace period for how long Pod Disruption Budget-protected workloads will be respected during any node draining operation. After this grace period, any workloads protected by Pod Disruption Budgets that have not been successfully drained from a node will be forcibly evicted. This is especially relevant to cluster upgrades. Valid values are in minutes and from 0 to 10080 minutes (1 week). 0 means that the MachinePool can be drained without any time limitation. This is the value is used a default for all NodePools. It can be overridden by specifying nodeDrainTimeoutMinutes for a given NodePool | int Optional |
| platform | Azure platform configuration | PlatformProfile Required |
| version | Version of the control plane components | VersionProfile Required |
HcpOpenShiftClusterProperties_STATUS
HCP cluster properties
Used by: HcpOpenShiftCluster_STATUS.
| Property | Description | Type |
|---|---|---|
| api | Shows the cluster API server profile | ApiProfile_STATUS Optional |
| autoscaling | Configure ClusterAutoscaling . | ClusterAutoscalingProfile_STATUS Optional |
| clusterImageRegistry | OpenShift internal image registry | ClusterImageRegistryProfile_STATUS Optional |
| console | Shows the cluster web console information | ConsoleProfile_STATUS Optional |
| cryptoRestrictions | Cryptographic restrictions for kernel and userspace libraries | HcpOpenShiftClusterProperties_CryptoRestrictions_STATUS Optional |
| dns | Cluster DNS configuration | DnsProfile_STATUS Optional |
| etcd | Configure ETCD. | EtcdProfile_STATUS Optional |
| imageDigestMirrors | imageDigestMirrors is a set of rules to allow pulling images from a mirrored registry by using digest specifications. WARNING: Updating this array will redeploy all node pools in the cluster. | ImageDigestMirror_STATUS[] Optional |
| ingress | The cluster ingress configuration | IngressProfile_STATUS Optional |
| network | Cluster network configuration | NetworkProfile_STATUS Optional |
| nodeDrainTimeoutMinutes | nodeDrainTimeoutMinutes is the grace period for how long Pod Disruption Budget-protected workloads will be respected during any node draining operation. After this grace period, any workloads protected by Pod Disruption Budgets that have not been successfully drained from a node will be forcibly evicted. This is especially relevant to cluster upgrades. Valid values are in minutes and from 0 to 10080 minutes (1 week). 0 means that the MachinePool can be drained without any time limitation. This is the value is used a default for all NodePools. It can be overridden by specifying nodeDrainTimeoutMinutes for a given NodePool | int Optional |
| platform | Azure platform configuration | PlatformProfile_STATUS Optional |
| provisioningState | The status of the last operation. | ProvisioningState_STATUS Optional |
| status | Status of the cluster resource | ResourceStatus_STATUS Optional |
| version | Version of the control plane components | VersionProfile_STATUS Optional |
HcpOpenShiftClustersExternalAuthOperatorSpec
Details for configuring operator behavior. Fields in this struct are interpreted by the operator directly rather than being passed to Azure
Used by: HcpOpenShiftClustersExternalAuth_Spec.
| Property | Description | Type |
|---|---|---|
| configMapExpressions | configures where to place operator written dynamic ConfigMaps (created with CEL expressions). | core.DestinationExpression[] Optional |
| secretExpressions | configures where to place operator written dynamic secrets (created with CEL expressions). | core.DestinationExpression[] Optional |
HcpOpenShiftClustersNodePoolOperatorSpec
Details for configuring operator behavior. Fields in this struct are interpreted by the operator directly rather than being passed to Azure
Used by: HcpOpenShiftClustersNodePool_Spec.
| Property | Description | Type |
|---|---|---|
| configMapExpressions | configures where to place operator written dynamic ConfigMaps (created with CEL expressions). | core.DestinationExpression[] Optional |
| secretExpressions | configures where to place operator written dynamic secrets (created with CEL expressions). | core.DestinationExpression[] Optional |
ManagedServiceIdentity
Managed service identity (system assigned and/or user assigned identities)
Used by: HcpOpenShiftCluster_Spec, and HcpOpenShiftClustersNodePool_Spec.
| Property | Description | Type |
|---|---|---|
| type | Type of managed service identity (where both SystemAssigned and UserAssigned types are allowed). | ManagedServiceIdentityType Required |
| userAssignedIdentities | The set of user assigned identities associated with the resource. The userAssignedIdentities dictionary keys will be ARM resource ids in the form: ‘/subscriptions/{subscriptionId}/resourceGroups/{resourceGroupName}/providers/Microsoft.ManagedIdentity/userAssignedIdentities/{identityName}. The dictionary values can be empty objects ({}) in requests. | UserAssignedIdentityDetails[] Optional |
ManagedServiceIdentity_STATUS
Managed service identity (system assigned and/or user assigned identities)
Used by: HcpOpenShiftCluster_STATUS, and HcpOpenShiftClustersNodePool_STATUS.
| Property | Description | Type |
|---|---|---|
| principalId | The service principal ID of the system assigned identity. This property will only be provided for a system assigned identity. | string Optional |
| tenantId | The tenant ID of the system assigned identity. This property will only be provided for a system assigned identity. | string Optional |
| type | Type of managed service identity (where both SystemAssigned and UserAssigned types are allowed). | ManagedServiceIdentityType_STATUS Optional |
| userAssignedIdentities | The set of user assigned identities associated with the resource. The userAssignedIdentities dictionary keys will be ARM resource ids in the form: ‘/subscriptions/{subscriptionId}/resourceGroups/{resourceGroupName}/providers/Microsoft.ManagedIdentity/userAssignedIdentities/{identityName}. The dictionary values can be empty objects ({}) in requests. | map[string]UserAssignedIdentity_STATUS Optional |
NodePoolProperties
Represents the node pool properties
Used by: HcpOpenShiftClustersNodePool_Spec.
| Property | Description | Type |
|---|---|---|
| autoRepair | Auto-repair | bool Optional |
| autoScaling | Representation of a autoscaling in a node pool. | NodePoolAutoScaling Optional |
| labels | Kubernetes labels to propagate to the NodePool Nodes Note that when the labels are updated this is only applied to newly create nodes in the Nodepool, existing node labels remain unchanged. | Label[] Optional |
| nodeDrainTimeoutMinutes | nodeDrainTimeoutMinutes is the grace period for how long Pod Disruption Budget-protected workloads will be respected during any node draining operation. After this grace period, any workloads protected by Pod Disruption Budgets that have not been successfully drained from a node will be forcibly evicted. This is especially relevant to cluster upgrades. Valid values are from 0 to 10080 minutes (1 week) . 0 means that the NodePool can be drained without any time limitation. If unset the cluster nodeDrainTimeoutMinutes value is used as a default. | int Optional |
| platform | Azure node pool platform configuration | NodePoolPlatformProfile Required |
| replicas | The number of worker nodes, it cannot be used together with autoscaling. Validation: |
- Minimum: 0
- Maximum: 200 (only when availabilityZone is not specified)
- No maximum when availabilityZone is specified| int
Optional| | taints| Taints for the nodes| Taint[]
Optional| | version| OpenShift version for the nodepool| NodePoolVersionProfile
Optional|
NodePoolProperties_STATUS
Represents the node pool properties
Used by: HcpOpenShiftClustersNodePool_STATUS.
| Property | Description | Type |
|---|---|---|
| autoRepair | Auto-repair | bool Optional |
| autoScaling | Representation of a autoscaling in a node pool. | NodePoolAutoScaling_STATUS Optional |
| labels | Kubernetes labels to propagate to the NodePool Nodes Note that when the labels are updated this is only applied to newly create nodes in the Nodepool, existing node labels remain unchanged. | Label_STATUS[] Optional |
| nodeDrainTimeoutMinutes | nodeDrainTimeoutMinutes is the grace period for how long Pod Disruption Budget-protected workloads will be respected during any node draining operation. After this grace period, any workloads protected by Pod Disruption Budgets that have not been successfully drained from a node will be forcibly evicted. This is especially relevant to cluster upgrades. Valid values are from 0 to 10080 minutes (1 week) . 0 means that the NodePool can be drained without any time limitation. If unset the cluster nodeDrainTimeoutMinutes value is used as a default. | int Optional |
| platform | Azure node pool platform configuration | NodePoolPlatformProfile_STATUS Optional |
| provisioningState | Provisioning state | ProvisioningState_STATUS Optional |
| replicas | The number of worker nodes, it cannot be used together with autoscaling. Validation: |
- Minimum: 0
- Maximum: 200 (only when availabilityZone is not specified)
- No maximum when availabilityZone is specified| int
Optional| | status| Status of the node pool resource| ResourceStatus_STATUS
Optional| | taints| Taints for the nodes| Taint_STATUS[]
Optional| | version| OpenShift version for the nodepool| NodePoolVersionProfile_STATUS
Optional|
SystemData_STATUS
Metadata pertaining to creation and last modification of the resource.
Used by: HcpOpenShiftCluster_STATUS, HcpOpenShiftClustersExternalAuth_STATUS, and HcpOpenShiftClustersNodePool_STATUS.
| Property | Description | Type |
|---|---|---|
| createdAt | The timestamp of resource creation (UTC). | string Optional |
| createdBy | The identity that created the resource. | string Optional |
| createdByType | The type of identity that created the resource. | SystemData_CreatedByType_STATUS Optional |
| lastModifiedAt | The timestamp of resource last modification (UTC) | string Optional |
| lastModifiedBy | The identity that last modified the resource. | string Optional |
| lastModifiedByType | The type of identity that last modified the resource. | SystemData_LastModifiedByType_STATUS Optional |
ApiProfile
Information about the API of a cluster.
Used by: HcpOpenShiftClusterProperties.
| Property | Description | Type |
|---|---|---|
| authorizedCidrs | The list of authorized IPv4 CIDR blocks allowed to access the API server. Maximum 500 entries. | string[] Optional |
| visibility | The internet visibility of the OpenShift API server | ApiProfile_Visibility Optional |
ApiProfile_STATUS
Information about the API of a cluster.
Used by: HcpOpenShiftClusterProperties_STATUS.
| Property | Description | Type |
|---|---|---|
| authorizedCidrs | The list of authorized IPv4 CIDR blocks allowed to access the API server. Maximum 500 entries. | string[] Optional |
| url | URL endpoint for the API server | string Optional |
| visibility | The internet visibility of the OpenShift API server | ApiProfile_Visibility_STATUS Optional |
ClusterAutoscalingProfile
ClusterAutoscaling specifies auto-scaling behavior that applies to all NodePools associated with a control plane.
Used by: HcpOpenShiftClusterProperties.
| Property | Description | Type |
|---|---|---|
| maxNodeProvisionTimeSeconds | maxNodeProvisionTimeSeconds is the maximum time to wait for node provisioning before considering the provisioning to be unsuccessful. The default is 900 seconds, or 15 minutes. | int Optional |
| maxNodesTotal | maxNodesTotal is the maximum allowable number of nodes for the Autoscaler scale out to be operational. The autoscaler will not grow the cluster beyond this number. If omitted, the autoscaler will not have a maximum limit. | int Optional |
| maxPodGracePeriodSeconds | maxPodGracePeriod is the maximum seconds to wait for graceful pod termination before scaling down a NodePool. The default is 600 seconds. | int Optional |
| podPriorityThreshold | podPriorityThreshold enables users to schedule “best-effort” pods, which shouldn’t trigger autoscaler actions, but only run when there are spare resources available. The default is -10. See the following for more details: https://github.com/kubernetes/autoscaler/blob/master/cluster-autoscaler/FAQ.md#how-does-cluster-autoscaler-work-with-pod-priority-and-preemption | int Optional |
ClusterAutoscalingProfile_STATUS
ClusterAutoscaling specifies auto-scaling behavior that applies to all NodePools associated with a control plane.
Used by: HcpOpenShiftClusterProperties_STATUS.
| Property | Description | Type |
|---|---|---|
| maxNodeProvisionTimeSeconds | maxNodeProvisionTimeSeconds is the maximum time to wait for node provisioning before considering the provisioning to be unsuccessful. The default is 900 seconds, or 15 minutes. | int Optional |
| maxNodesTotal | maxNodesTotal is the maximum allowable number of nodes for the Autoscaler scale out to be operational. The autoscaler will not grow the cluster beyond this number. If omitted, the autoscaler will not have a maximum limit. | int Optional |
| maxPodGracePeriodSeconds | maxPodGracePeriod is the maximum seconds to wait for graceful pod termination before scaling down a NodePool. The default is 600 seconds. | int Optional |
| podPriorityThreshold | podPriorityThreshold enables users to schedule “best-effort” pods, which shouldn’t trigger autoscaler actions, but only run when there are spare resources available. The default is -10. See the following for more details: https://github.com/kubernetes/autoscaler/blob/master/cluster-autoscaler/FAQ.md#how-does-cluster-autoscaler-work-with-pod-priority-and-preemption | int Optional |
ClusterImageRegistryProfile
OpenShift cluster image registry
Used by: HcpOpenShiftClusterProperties.
| Property | Description | Type |
|---|---|---|
| state | state indicates the desired ImageStream-backed cluster image registry installation mode. This can only be set during cluster creation and cannot be changed after cluster creation. Enabled means the ImageStream-backed image registry will be run as pods on worker nodes in the cluster. Disabled means the ImageStream-backed image registry will not be present in the cluster. The default is Enabled. | ClusterImageRegistryProfile_State Optional |
ClusterImageRegistryProfile_STATUS
OpenShift cluster image registry
Used by: HcpOpenShiftClusterProperties_STATUS.
| Property | Description | Type |
|---|---|---|
| state | state indicates the desired ImageStream-backed cluster image registry installation mode. This can only be set during cluster creation and cannot be changed after cluster creation. Enabled means the ImageStream-backed image registry will be run as pods on worker nodes in the cluster. Disabled means the ImageStream-backed image registry will not be present in the cluster. The default is Enabled. | ClusterImageRegistryProfile_State_STATUS Optional |
ConsoleProfile_STATUS
Configuration of the cluster web console
Used by: HcpOpenShiftClusterProperties_STATUS.
| Property | Description | Type |
|---|---|---|
| url | The cluster web console URL endpoint | string Optional |
DnsProfile
DNS contains the DNS settings of the cluster
Used by: HcpOpenShiftClusterProperties.
| Property | Description | Type |
|---|---|---|
| baseDomainPrefix | BaseDomainPrefix is the unique name of the cluster representing the OpenShift’s cluster name. BaseDomainPrefix is the name that will appear in the cluster’s DNS, provisioned cloud providers resources | string Optional |
DnsProfile_STATUS
DNS contains the DNS settings of the cluster
Used by: HcpOpenShiftClusterProperties_STATUS.
| Property | Description | Type |
|---|---|---|
| baseDomain | BaseDomain is the base DNS domain of the cluster. | string Optional |
| baseDomainPrefix | BaseDomainPrefix is the unique name of the cluster representing the OpenShift’s cluster name. BaseDomainPrefix is the name that will appear in the cluster’s DNS, provisioned cloud providers resources | string Optional |
EtcdProfile
The ETCD settings and configuration options.
Used by: HcpOpenShiftClusterProperties.
| Property | Description | Type |
|---|---|---|
| dataEncryption | ETCD Data Encryption settings. If not specified platform managed keys are used. | EtcdDataEncryptionProfile Optional |
EtcdProfile_STATUS
The ETCD settings and configuration options.
Used by: HcpOpenShiftClusterProperties_STATUS.
| Property | Description | Type |
|---|---|---|
| dataEncryption | ETCD Data Encryption settings. If not specified platform managed keys are used. | EtcdDataEncryptionProfile_STATUS Optional |
ExternalAuthClaimProfile
External Auth claim profile
Used by: ExternalAuthProperties.
| Property | Description | Type |
|---|---|---|
| mappings | The claim mappings | TokenClaimMappingsProfile Required |
| validationRules | The claim validation rules | TokenClaimValidationRule[] Optional |
ExternalAuthClaimProfile_STATUS
External Auth claim profile
Used by: ExternalAuthProperties_STATUS.
| Property | Description | Type |
|---|---|---|
| mappings | The claim mappings | TokenClaimMappingsProfile_STATUS Optional |
| validationRules | The claim validation rules | TokenClaimValidationRule_STATUS[] Optional |
ExternalAuthClientProfile
External Auth client profile This configures how on-cluster, platform clients should request tokens from the identity provider.
Used by: ExternalAuthProperties.
| Property | Description | Type |
|---|---|---|
| clientId | External Auth client id The clientId must appear in the audience field of the TokenIssuerProfile. | string Required |
| component | External Auth client component | ExternalAuthClientComponentProfile Required |
| extraScopes | external auth client scopes This is useful if you have configured claim mappings that requires specific scopes to be requested beyond the standard OIDC scopes. When omitted, no additional scopes are requested. | string[] Optional |
| type | Determines the OIDC provider client type. | ExternalAuthClientType Required |
ExternalAuthClientProfile_STATUS
External Auth client profile This configures how on-cluster, platform clients should request tokens from the identity provider.
Used by: ExternalAuthProperties_STATUS.
| Property | Description | Type |
|---|---|---|
| clientId | External Auth client id The clientId must appear in the audience field of the TokenIssuerProfile. | string Required |
| component | External Auth client component | ExternalAuthClientComponentProfile_STATUS Required |
| extraScopes | external auth client scopes This is useful if you have configured claim mappings that requires specific scopes to be requested beyond the standard OIDC scopes. When omitted, no additional scopes are requested. | string[] Optional |
| type | Determines the OIDC provider client type. | ExternalAuthClientType_STATUS Required |
ExternalAuthProvisioningState_STATUS
The resource provisioning state.
Used by: ExternalAuthProperties_STATUS.
| Value | Description |
|---|---|
| “Accepted” | |
| “AwaitingSecret” | |
| “Canceled” | |
| “Deleting” | |
| “Failed” | |
| “Provisioning” | |
| “Succeeded” | |
| “Updating” |
HcpOpenShiftClusterOperatorSecrets
Used by: HcpOpenShiftClusterOperatorSpec.
| Property | Description | Type |
|---|---|---|
| adminCredentials | indicates where the AdminCredentials secret should be placed. If omitted, the secret will not be retrieved from Azure. | genruntime.SecretDestination Optional |
HcpOpenShiftClusterProperties_CryptoRestrictions
Used by: HcpOpenShiftClusterProperties.
| Value | Description |
|---|---|
| “FIPS” | |
| “None” |
HcpOpenShiftClusterProperties_CryptoRestrictions_STATUS
Used by: HcpOpenShiftClusterProperties_STATUS.
| Value | Description |
|---|---|
| “FIPS” | |
| “None” |
ImageDigestMirror
ImageDigestMirror specifies a set of mirror registries to redirect image pulls targeting the specified source registries.
Used by: HcpOpenShiftClusterProperties.
| Property | Description | Type |
|---|---|---|
| mirrors | mirrors is zero or more locations that may also contain the same images. No mirror will be configured if not specified. Images can be pulled from these mirrors only if they are referenced by their digests. The mirrored location is obtained by replacing the part of the input reference that matches source by the mirrors entry, e.g. for registry.redhat.io/product/repo reference, a (source, mirror) pair *.redhat.io, mirror.local/redhat causes a mirror.local/redhat/product/repo repository to be used. The order of mirrors in this list is treated as the user’s desired priority, while source is by default considered lower priority than all mirrors. If no mirror is specified or all image pulls from the mirror list fail, the image will continue to be pulled from the repository in the pull spec. Other cluster configuration, including (but not limited to) other imageDigestMirrors objects, may impact the exact order mirrors are contacted in, or some mirrors may be contacted in parallel, so this should be considered a preference rather than a guarantee of ordering. mirrors uses one of the following formats: |
- host[:port]
- host[:port]/namespace[/namespace…]
- host[:port]/namespace[/namespace…]/repo
for more information about the format, see: https://github.com/containers/image/blob/main/docs/containers-registries.conf.5.md#choosing-a-registry-toml-table| ImageRepository[]
Required| | source| source matches the repository that users refer to, e.g. in image pull specifications. Setting source to a registry hostname, e.g. docker.io, quay.io, or registry.redhat.io, will match the image pull specification of the corresponding registry. source uses one of the following formats:
- host[:port]
- host[:port]/namespace[/namespace…]
- host[:port]/namespace[/namespace…]/repo
- [*.]host
for more information about the format, see: https://github.com/containers/image/blob/main/docs/containers-registries.conf.5.md#choosing-a-registry-toml-table| ImageRepository
Required|
ImageDigestMirror_STATUS
ImageDigestMirror specifies a set of mirror registries to redirect image pulls targeting the specified source registries.
Used by: HcpOpenShiftClusterProperties_STATUS.
| Property | Description | Type |
|---|---|---|
| mirrors | mirrors is zero or more locations that may also contain the same images. No mirror will be configured if not specified. Images can be pulled from these mirrors only if they are referenced by their digests. The mirrored location is obtained by replacing the part of the input reference that matches source by the mirrors entry, e.g. for registry.redhat.io/product/repo reference, a (source, mirror) pair *.redhat.io, mirror.local/redhat causes a mirror.local/redhat/product/repo repository to be used. The order of mirrors in this list is treated as the user’s desired priority, while source is by default considered lower priority than all mirrors. If no mirror is specified or all image pulls from the mirror list fail, the image will continue to be pulled from the repository in the pull spec. Other cluster configuration, including (but not limited to) other imageDigestMirrors objects, may impact the exact order mirrors are contacted in, or some mirrors may be contacted in parallel, so this should be considered a preference rather than a guarantee of ordering. mirrors uses one of the following formats: |
- host[:port]
- host[:port]/namespace[/namespace…]
- host[:port]/namespace[/namespace…]/repo
for more information about the format, see: https://github.com/containers/image/blob/main/docs/containers-registries.conf.5.md#choosing-a-registry-toml-table| ImageRepository_STATUS[]
Required| | source| source matches the repository that users refer to, e.g. in image pull specifications. Setting source to a registry hostname, e.g. docker.io, quay.io, or registry.redhat.io, will match the image pull specification of the corresponding registry. source uses one of the following formats:
- host[:port]
- host[:port]/namespace[/namespace…]
- host[:port]/namespace[/namespace…]/repo
- [*.]host
for more information about the format, see: https://github.com/containers/image/blob/main/docs/containers-registries.conf.5.md#choosing-a-registry-toml-table| ImageRepository_STATUS
Required|
IngressProfile
Information about the Ingress of a cluster.
Used by: HcpOpenShiftClusterProperties.
| Property | Description | Type |
|---|---|---|
| type | The type of the default cluster ingress. | IngressProfile_Type Optional |
IngressProfile_STATUS
Information about the Ingress of a cluster.
Used by: HcpOpenShiftClusterProperties_STATUS.
| Property | Description | Type |
|---|---|---|
| type | The type of the default cluster ingress. | IngressProfile_Type_STATUS Optional |
Label
Label represents the Kubernetes label
Used by: NodePoolProperties.
| Property | Description | Type |
|---|---|---|
| key | The key of the label | string Required |
| value | The value of the label | string Optional |
Label_STATUS
Label represents the Kubernetes label
Used by: NodePoolProperties_STATUS.
| Property | Description | Type |
|---|---|---|
| key | The key of the label | string Optional |
| value | The value of the label | string Optional |
ManagedServiceIdentityType
Type of managed service identity (where both SystemAssigned and UserAssigned types are allowed).
Used by: ManagedServiceIdentity.
| Value | Description |
|---|---|
| “None” | |
| “SystemAssigned” | |
| “SystemAssigned,UserAssigned” | |
| “UserAssigned” |
ManagedServiceIdentityType_STATUS
Type of managed service identity (where both SystemAssigned and UserAssigned types are allowed).
Used by: ManagedServiceIdentity_STATUS.
| Value | Description |
|---|---|
| “None” | |
| “SystemAssigned” | |
| “SystemAssigned,UserAssigned” | |
| “UserAssigned” |
NetworkProfile
OpenShift networking configuration
Used by: HcpOpenShiftClusterProperties.
| Property | Description | Type |
|---|---|---|
| hostPrefix | Network host prefix | int Optional |
| machineCidr | The CIDR block from which to assign machine IP addresses | string Optional |
| networkType | The main controller responsible for rendering the core networking components | NetworkProfile_NetworkType Optional |
| podCidr | The CIDR of the pod IP addresses | string Optional |
| serviceCidr | The CIDR block for assigned service IPs | string Optional |
NetworkProfile_STATUS
OpenShift networking configuration
Used by: HcpOpenShiftClusterProperties_STATUS.
| Property | Description | Type |
|---|---|---|
| hostPrefix | Network host prefix | int Optional |
| machineCidr | The CIDR block from which to assign machine IP addresses | string Optional |
| networkType | The main controller responsible for rendering the core networking components | NetworkProfile_NetworkType_STATUS Optional |
| podCidr | The CIDR of the pod IP addresses | string Optional |
| serviceCidr | The CIDR block for assigned service IPs | string Optional |
NodePoolAutoScaling
Node pool autoscaling
Used by: NodePoolProperties.
| Property | Description | Type |
|---|---|---|
| max | The maximum number of nodes in the node pool. Validation: |
-
Minimum: 0 (must be >= min)
-
Maximum: 200 (only when availabilityZone is not specified)
-
No maximum when availabilityZone is specified| int
Optional| | min| The minimum number of nodes in the node pool. Validation: -
Minimum: 0
-
Maximum: 200 (only when availabilityZone is not specified)
-
No maximum when availabilityZone is specified| int
Optional|
NodePoolAutoScaling_STATUS
Node pool autoscaling
Used by: NodePoolProperties_STATUS.
| Property | Description | Type |
|---|---|---|
| max | The maximum number of nodes in the node pool. Validation: |
-
Minimum: 0 (must be >= min)
-
Maximum: 200 (only when availabilityZone is not specified)
-
No maximum when availabilityZone is specified| int
Optional| | min| The minimum number of nodes in the node pool. Validation: -
Minimum: 0
-
Maximum: 200 (only when availabilityZone is not specified)
-
No maximum when availabilityZone is specified| int
Optional|
NodePoolPlatformProfile
Azure node pool platform configuration
Used by: NodePoolProperties.
| Property | Description | Type |
|---|---|---|
| availabilityZone | The availability zone for the node pool. Please read the documentation to see which regions support availability zones |
-
https://learn.microsoft.com/en-us/azure/availability-zones/az-overview| string
Optional| | enableEncryptionAtHost| Whether to enable host based OS and data drive encryption. - https://learn.microsoft.com/en-us/azure/virtual-machines/disk-encryption#encryption-at-host---end-to-end-encryption-for-your-vm-data| bool
Optional| | osDisk| The settings and configuration options for OSDisk| OsDiskProfile
Optional| | subnetReference| The Azure resource ID of the worker subnet Note that a subnet cannot be reused between ARO-HCP Clusters, however the same subnet can be used for NodePools of the same cluster.| genruntime.ResourceReference
Optional| | vmSize| The VM size according to the documentation: -
https://learn.microsoft.com/en-us/azure/virtual-machines/sizes| string
Required|
NodePoolPlatformProfile_STATUS
Azure node pool platform configuration
Used by: NodePoolProperties_STATUS.
| Property | Description | Type |
|---|---|---|
| availabilityZone | The availability zone for the node pool. Please read the documentation to see which regions support availability zones |
-
https://learn.microsoft.com/en-us/azure/availability-zones/az-overview| string
Optional| | enableEncryptionAtHost| Whether to enable host based OS and data drive encryption. - https://learn.microsoft.com/en-us/azure/virtual-machines/disk-encryption#encryption-at-host---end-to-end-encryption-for-your-vm-data| bool
Optional| | osDisk| The settings and configuration options for OSDisk| OsDiskProfile_STATUS
Optional| | subnetId| The Azure resource ID of the worker subnet Note that a subnet cannot be reused between ARO-HCP Clusters, however the same subnet can be used for NodePools of the same cluster.| string
Optional| | vmSize| The VM size according to the documentation: -
https://learn.microsoft.com/en-us/azure/virtual-machines/sizes| string
Optional|
NodePoolVersionProfile
Versions represents an OpenShift version.
Used by: NodePoolProperties.
| Property | Description | Type |
|---|---|---|
| channelGroup | ChannelGroup is the name of the set to which this version belongs. Each version belongs to only a single set. If not specified, the default value is stable. |
string Optional |
| id | ID is the unique identifier of the version. | string Required |
NodePoolVersionProfile_STATUS
Versions represents an OpenShift version.
Used by: NodePoolProperties_STATUS.
| Property | Description | Type |
|---|---|---|
| channelGroup | ChannelGroup is the name of the set to which this version belongs. Each version belongs to only a single set. If not specified, the default value is stable. |
string Optional |
| id | ID is the unique identifier of the version. | string Optional |
PlatformProfile
Azure specific configuration
Used by: HcpOpenShiftClusterProperties.
| Property | Description | Type |
|---|---|---|
| managedResourceGroup | Resource group name to put cluster resources If not specified then a unique name is generated from the following pattern “aro-hcp-” + clusterName + “-” + UUID where clusterName means the hcpOpenShiftClusters resource name (up to 45 characters) followed by a 16-byte universally unique identifier per RFC 4122. | string Optional |
| networkSecurityGroupReference | ResourceId for the NSG (network security group) attached to the cluster subnet Note that NSGs cannot be reused for other ARO-HCP clusters. | genruntime.ResourceReference Required |
| operatorsAuthentication | The configuration that the operators of the cluster have to authenticate to Azure | OperatorsAuthenticationProfile Required |
| outboundType | The core outgoing configuration | PlatformProfile_OutboundType Optional |
| subnetReference | The Azure resource ID of the worker subnet Note that a subnet cannot be reused between ARO-HCP Clusters. | genruntime.ResourceReference Required |
| vnetIntegrationSubnetReference | The Azure resource ID of a subnet that enables direct, private network connectivity between the hosted control plane and your cluster’s nodes. This subnet must be dedicated to ARO HCP and cannot be shared with the cluster subnet or any node pool subnets. | genruntime.ResourceReference Required |
PlatformProfile_STATUS
Azure specific configuration
Used by: HcpOpenShiftClusterProperties_STATUS.
| Property | Description | Type |
|---|---|---|
| issuerUrl | URL for the OIDC provider to be used for authentication to authenticate against user Azure cloud account | string Optional |
| managedResourceGroup | Resource group name to put cluster resources If not specified then a unique name is generated from the following pattern “aro-hcp-” + clusterName + “-” + UUID where clusterName means the hcpOpenShiftClusters resource name (up to 45 characters) followed by a 16-byte universally unique identifier per RFC 4122. | string Optional |
| networkSecurityGroupId | ResourceId for the NSG (network security group) attached to the cluster subnet Note that NSGs cannot be reused for other ARO-HCP clusters. | string Optional |
| operatorsAuthentication | The configuration that the operators of the cluster have to authenticate to Azure | OperatorsAuthenticationProfile_STATUS Optional |
| outboundType | The core outgoing configuration | PlatformProfile_OutboundType_STATUS Optional |
| subnetId | The Azure resource ID of the worker subnet Note that a subnet cannot be reused between ARO-HCP Clusters. | string Optional |
| vnetIntegrationSubnetId | The Azure resource ID of a subnet that enables direct, private network connectivity between the hosted control plane and your cluster’s nodes. This subnet must be dedicated to ARO HCP and cannot be shared with the cluster subnet or any node pool subnets. | string Optional |
ProvisioningState_STATUS
The resource provisioning state.
Used by: HcpOpenShiftClusterProperties_STATUS, and NodePoolProperties_STATUS.
| Value | Description |
|---|---|
| “Accepted” | |
| “Canceled” | |
| “Deleting” | |
| “Failed” | |
| “Provisioning” | |
| “Succeeded” | |
| “Updating” |
ResourceStatus_STATUS
ResourceStatus represents the observed status of the resource.
Used by: ExternalAuthProperties_STATUS, HcpOpenShiftClusterProperties_STATUS, and NodePoolProperties_STATUS.
| Property | Description | Type |
|---|---|---|
| conditions | The conditions on the resource | Condition_STATUS[] Optional |
SystemData_CreatedByType_STATUS
Used by: SystemData_STATUS.
| Value | Description |
|---|---|
| “Application” | |
| “Key” | |
| “ManagedIdentity” | |
| “User” |
SystemData_LastModifiedByType_STATUS
Used by: SystemData_STATUS.
| Value | Description |
|---|---|
| “Application” | |
| “Key” | |
| “ManagedIdentity” | |
| “User” |
Taint
Taint is controlling the node taint and its effects
Used by: NodePoolProperties.
| Property | Description | Type |
|---|---|---|
| effect | The effect of the taint | Effect Required |
| key | The key of the taint | string Required |
| value | The value of the taint | string Optional |
Taint_STATUS
Taint is controlling the node taint and its effects
Used by: NodePoolProperties_STATUS.
| Property | Description | Type |
|---|---|---|
| effect | The effect of the taint | Effect_STATUS Optional |
| key | The key of the taint | string Optional |
| value | The value of the taint | string Optional |
TokenIssuerProfile
Token issuer profile This configures how the platform interacts with the identity provider and how tokens issued from the identity provider are evaluated by the Kubernetes API server.
Used by: ExternalAuthProperties.
| Property | Description | Type |
|---|---|---|
| audiences | This configures the acceptable audiences the JWT token, issued by the identity provider, must be issued to. At least one of the entries must match the aud claim in the JWT token. audiences must contain at least one entry and must not exceed ten entries. |
string[] Required |
| ca | The issuer of the token Certificate bundle to use to validate server certificates for the configured URL. It must be PEM encoded and when not specified, the system trust is used. | string Optional |
| url | This configures the URL used to issue tokens by the identity provider. The Kubernetes API server determines how authentication tokens should be handled by matching the iss claim in the JWT to the issuerURL of configured identity providers. issuerURL must use the https scheme. |
string Required |
TokenIssuerProfile_STATUS
Token issuer profile This configures how the platform interacts with the identity provider and how tokens issued from the identity provider are evaluated by the Kubernetes API server.
Used by: ExternalAuthProperties_STATUS.
| Property | Description | Type |
|---|---|---|
| audiences | This configures the acceptable audiences the JWT token, issued by the identity provider, must be issued to. At least one of the entries must match the aud claim in the JWT token. audiences must contain at least one entry and must not exceed ten entries. |
string[] Optional |
| ca | The issuer of the token Certificate bundle to use to validate server certificates for the configured URL. It must be PEM encoded and when not specified, the system trust is used. | string Optional |
| url | This configures the URL used to issue tokens by the identity provider. The Kubernetes API server determines how authentication tokens should be handled by matching the iss claim in the JWT to the issuerURL of configured identity providers. issuerURL must use the https scheme. |
string Optional |
UserAssignedIdentity_STATUS
User assigned identity properties
Used by: ManagedServiceIdentity_STATUS.
| Property | Description | Type |
|---|---|---|
| clientId | The client ID of the assigned identity. | string Optional |
| principalId | The principal ID of the assigned identity. | string Optional |
UserAssignedIdentityDetails
Information about the user assigned identity for the resource
Used by: ManagedServiceIdentity.
| Property | Description | Type |
|---|---|---|
| reference | genruntime.ResourceReference Optional |
VersionProfile
Versions represents an OpenShift version.
Used by: HcpOpenShiftClusterProperties.
| Property | Description | Type |
|---|---|---|
| channelGroup | ChannelGroup is the name of the set to which this version belongs. Each version belongs to only a single set. If not specified, the default value is stable. |
string Optional |
| id | ID is the desired X.Y version of the cluster control plane. | string Required |
VersionProfile_STATUS
Versions represents an OpenShift version.
Used by: HcpOpenShiftClusterProperties_STATUS.
| Property | Description | Type |
|---|---|---|
| channelGroup | ChannelGroup is the name of the set to which this version belongs. Each version belongs to only a single set. If not specified, the default value is stable. |
string Optional |
| id | ID is the desired X.Y version of the cluster control plane. | string Optional |
ApiProfile_Visibility
Used by: ApiProfile.
| Value | Description |
|---|---|
| “Private” | |
| “Public” |
ApiProfile_Visibility_STATUS
Used by: ApiProfile_STATUS.
| Value | Description |
|---|---|
| “Private” | |
| “Public” |
ClusterImageRegistryProfile_State
Used by: ClusterImageRegistryProfile.
| Value | Description |
|---|---|
| “Disabled” | |
| “Enabled” |
ClusterImageRegistryProfile_State_STATUS
Used by: ClusterImageRegistryProfile_STATUS.
| Value | Description |
|---|---|
| “Disabled” | |
| “Enabled” |
Condition_STATUS
Condition represents an observation of a resource’s state.
Used by: ResourceStatus_STATUS.
| Property | Description | Type |
|---|---|---|
| lastTransitionTime | The last time the condition transitioned from one status to another. | string Required |
| message | A human readable message indicating details about the transition. This may be an empty string. | string Required |
| reason | A programmatic identifier indicating the reason for the condition’s last transition. This value should be a CamelCase string. | string Required |
| status | The status of the condition. | StatusType_STATUS Required |
| type | Type of the condition. This is a PascalCase identifier representing the type of the condition. | ConditionType_STATUS Required |
Effect
The taint effect the same as in Kubernetes
Used by: Taint.
| Value | Description |
|---|---|
| “NoExecute” | |
| “NoSchedule” | |
| “PreferNoSchedule” |
Effect_STATUS
The taint effect the same as in Kubernetes
Used by: Taint_STATUS.
| Value | Description |
|---|---|
| “NoExecute” | |
| “NoSchedule” | |
| “PreferNoSchedule” |
EtcdDataEncryptionProfile
The ETCD data encryption settings.
Used by: EtcdProfile.
| Property | Description | Type |
|---|---|---|
| customerManaged | Specify customer managed encryption key details. Required when keyManagementMode is “CustomerManaged”. | CustomerManagedEncryptionProfile Optional |
| keyManagementMode | Specify the key management strategy used for the encryption key that encrypts the ETCD data. | EtcdDataEncryptionKeyManagementModeType Required |
EtcdDataEncryptionProfile_STATUS
The ETCD data encryption settings.
Used by: EtcdProfile_STATUS.
| Property | Description | Type |
|---|---|---|
| customerManaged | Specify customer managed encryption key details. Required when keyManagementMode is “CustomerManaged”. | CustomerManagedEncryptionProfile_STATUS Optional |
| keyManagementMode | Specify the key management strategy used for the encryption key that encrypts the ETCD data. | EtcdDataEncryptionKeyManagementModeType_STATUS Optional |
ExternalAuthClientComponentProfile
External Auth component profile Must have unique namespace/name pairs.
Used by: ExternalAuthClientProfile.
| Property | Description | Type |
|---|---|---|
| authClientNamespace | The namespace of the external Auth client This specifies the namespace in which the platform component being configured to use the identity provider as an authentication mode is running. It is used in combination with name as a unique identifier. | string Required |
| name | The name of the external auth client This specifies the name of the platform component being configured to use the identity provider as an authentication mode. It is used in combination with namespace as a unique identifier. | string Required |
ExternalAuthClientComponentProfile_STATUS
External Auth component profile Must have unique namespace/name pairs.
Used by: ExternalAuthClientProfile_STATUS.
| Property | Description | Type |
|---|---|---|
| authClientNamespace | The namespace of the external Auth client This specifies the namespace in which the platform component being configured to use the identity provider as an authentication mode is running. It is used in combination with name as a unique identifier. | string Required |
| name | The name of the external auth client This specifies the name of the platform component being configured to use the identity provider as an authentication mode. It is used in combination with namespace as a unique identifier. | string Required |
ExternalAuthClientType
Representation of the possible values of an external authentication client’s type
Used by: ExternalAuthClientProfile.
| Value | Description |
|---|---|
| “Confidential” | |
| “Public” |
ExternalAuthClientType_STATUS
Representation of the possible values of an external authentication client’s type
Used by: ExternalAuthClientProfile_STATUS.
| Value | Description |
|---|---|
| “Confidential” | |
| “Public” |
ImageRepository
Used by: ImageDigestMirror, and ImageDigestMirror.
ImageRepository_STATUS
Used by: ImageDigestMirror_STATUS, and ImageDigestMirror_STATUS.
IngressProfile_Type
Used by: IngressProfile.
| Value | Description |
|---|---|
| “Disabled” | |
| “Private” | |
| “Public” |
IngressProfile_Type_STATUS
Used by: IngressProfile_STATUS.
| Value | Description |
|---|---|
| “Disabled” | |
| “Private” | |
| “Public” |
NetworkProfile_NetworkType
Used by: NetworkProfile.
| Value | Description |
|---|---|
| “OVNKubernetes” | |
| “Other” |
NetworkProfile_NetworkType_STATUS
Used by: NetworkProfile_STATUS.
| Value | Description |
|---|---|
| “OVNKubernetes” | |
| “Other” |
OperatorsAuthenticationProfile
The configuration that the operators of the cluster have to authenticate to Azure.
Used by: PlatformProfile.
| Property | Description | Type |
|---|---|---|
| userAssignedIdentities | Represents the information related to Azure User-Assigned managed identities needed to perform Operators authentication based on Azure User-Assigned Managed Identities | UserAssignedIdentitiesProfile Required |
OperatorsAuthenticationProfile_STATUS
The configuration that the operators of the cluster have to authenticate to Azure.
Used by: PlatformProfile_STATUS.
| Property | Description | Type |
|---|---|---|
| userAssignedIdentities | Represents the information related to Azure User-Assigned managed identities needed to perform Operators authentication based on Azure User-Assigned Managed Identities | UserAssignedIdentitiesProfile_STATUS Optional |
OsDiskProfile
The settings and configuration options for OSDisk
Used by: NodePoolPlatformProfile.
| Property | Description | Type |
|---|---|---|
| diskStorageAccountType | The type of the disk storage account |
-
https://learn.microsoft.com/en-us/azure/virtual-machines/disks-types| OsDiskProfile_DiskStorageAccountType
Optional| | diskType| The type of the OS disk. -
https://learn.microsoft.com/en-us/azure/virtual-machines/ephemeral-os-disks| OsDiskProfile_DiskType
Optional| | encryptionSetReference| The ID of the DiskEncryptionSet resource to use to encrypt the OS disks for the VMs. This needs to exist in the same subscription id listed in the Hosted Cluster, HostedCluster.Spec.Platform.Azure.SubscriptionID. DiskEncryptionSetID should also exist in a resource group under the same subscription id and the same location listed in the Hosted Cluster, HostedCluster.Spec.Platform.Azure.Location. Details on how to create a Disk Encryption Set can be found here: https://learn.microsoft.com/en-us/azure/virtual-machines/disks-enable-customer-managed-keys-portal#set-up-your-disk-encryption-set| genruntime.ResourceReference
Optional| | sizeGiB| The OS disk size in GiB. Maximum is 4095 GiB for Managed disks. For Ephemeral disks, the maximum is 2040 GiB; Azure may enforce a lower effective limit based on the selected VM size’s local cache, temp, or NVMe capacity.| int
Optional|
OsDiskProfile_STATUS
The settings and configuration options for OSDisk
Used by: NodePoolPlatformProfile_STATUS.
| Property | Description | Type |
|---|---|---|
| diskStorageAccountType | The type of the disk storage account |
-
https://learn.microsoft.com/en-us/azure/virtual-machines/disks-types| OsDiskProfile_DiskStorageAccountType_STATUS
Optional| | diskType| The type of the OS disk. -
https://learn.microsoft.com/en-us/azure/virtual-machines/ephemeral-os-disks| OsDiskProfile_DiskType_STATUS
Optional| | encryptionSetId| The ID of the DiskEncryptionSet resource to use to encrypt the OS disks for the VMs. This needs to exist in the same subscription id listed in the Hosted Cluster, HostedCluster.Spec.Platform.Azure.SubscriptionID. DiskEncryptionSetID should also exist in a resource group under the same subscription id and the same location listed in the Hosted Cluster, HostedCluster.Spec.Platform.Azure.Location. Details on how to create a Disk Encryption Set can be found here: https://learn.microsoft.com/en-us/azure/virtual-machines/disks-enable-customer-managed-keys-portal#set-up-your-disk-encryption-set| string
Optional| | sizeGiB| The OS disk size in GiB. Maximum is 4095 GiB for Managed disks. For Ephemeral disks, the maximum is 2040 GiB; Azure may enforce a lower effective limit based on the selected VM size’s local cache, temp, or NVMe capacity.| int
Optional|
PlatformProfile_OutboundType
Used by: PlatformProfile.
| Value | Description |
|---|---|
| “LoadBalancer” |
PlatformProfile_OutboundType_STATUS
Used by: PlatformProfile_STATUS.
| Value | Description |
|---|---|
| “LoadBalancer” |
TokenClaimMappingsProfile
External Auth claim mappings profile. At a minimum username or groups must be defined.
Used by: ExternalAuthClaimProfile.
| Property | Description | Type |
|---|---|---|
| groups | The claim mappings groups. | GroupClaimProfile Optional |
| username | The claim mappings username. | UsernameClaimProfile Required |
TokenClaimMappingsProfile_STATUS
External Auth claim mappings profile. At a minimum username or groups must be defined.
Used by: ExternalAuthClaimProfile_STATUS.
| Property | Description | Type |
|---|---|---|
| groups | The claim mappings groups. | GroupClaimProfile_STATUS Optional |
| username | The claim mappings username. | UsernameClaimProfile_STATUS Optional |
TokenClaimValidationRule
External Auth claim validation rule
Used by: ExternalAuthClaimProfile.
| Property | Description | Type |
|---|---|---|
| requiredClaim | The required claim rule to be applied. | TokenRequiredClaim Optional |
| type | This configures the type of the validation rule. It defaults to “RequiredClaim” | TokenClaimValidationRule_Type Optional |
TokenClaimValidationRule_STATUS
External Auth claim validation rule
Used by: ExternalAuthClaimProfile_STATUS.
| Property | Description | Type |
|---|---|---|
| requiredClaim | The required claim rule to be applied. | TokenRequiredClaim_STATUS Optional |
| type | This configures the type of the validation rule. It defaults to “RequiredClaim” | TokenClaimValidationRule_Type_STATUS Optional |
ConditionType_STATUS
Representation of the possible condition types.
Used by: Condition_STATUS.
| Value | Description |
|---|---|
| “Available” | |
| “Degraded” | |
| “Progressing” |
CustomerManagedEncryptionProfile
Customer managed encryption key profile.
Used by: EtcdDataEncryptionProfile.
| Property | Description | Type |
|---|---|---|
| encryptionType | The encryption type used. By default, “KMS” is used. | CustomerManagedEncryptionProfile_EncryptionType Optional |
| kms | The Key Management Service (KMS) encryption key details. Required when encryptionType is “KMS”. | KmsEncryptionProfile Optional |
CustomerManagedEncryptionProfile_STATUS
Customer managed encryption key profile.
Used by: EtcdDataEncryptionProfile_STATUS.
| Property | Description | Type |
|---|---|---|
| encryptionType | The encryption type used. By default, “KMS” is used. | CustomerManagedEncryptionProfile_EncryptionType_STATUS Optional |
| kms | The Key Management Service (KMS) encryption key details. Required when encryptionType is “KMS”. | KmsEncryptionProfile_STATUS Optional |
EtcdDataEncryptionKeyManagementModeType
The encryption key management mode types supported for ETCD data encryption.
Used by: EtcdDataEncryptionProfile.
| Value | Description |
|---|---|
| “CustomerManaged” |
EtcdDataEncryptionKeyManagementModeType_STATUS
The encryption key management mode types supported for ETCD data encryption.
Used by: EtcdDataEncryptionProfile_STATUS.
| Value | Description |
|---|---|
| “CustomerManaged” |
GroupClaimProfile
External Auth claim profile This configures how the groups of a cluster identity should be constructed from the claims in a JWT token issued by the identity provider. When referencing a claim, if the claim is present in the JWT token, its value must be a list of groups separated by a comma (’,’). For example - ‘“example”’ and ‘“exampleOne”, “exampleTwo”, “exampleThree”’ are valid claim values.
Used by: TokenClaimMappingsProfile.
| Property | Description | Type |
|---|---|---|
| claim | Claim name of the external profile | string Required |
| prefix | Prefix for the claim external profile If this is specified prefixPolicy will be set to “Prefix” by default | string Optional |
GroupClaimProfile_STATUS
External Auth claim profile This configures how the groups of a cluster identity should be constructed from the claims in a JWT token issued by the identity provider. When referencing a claim, if the claim is present in the JWT token, its value must be a list of groups separated by a comma (’,’). For example - ‘“example”’ and ‘“exampleOne”, “exampleTwo”, “exampleThree”’ are valid claim values.
Used by: TokenClaimMappingsProfile_STATUS.
| Property | Description | Type |
|---|---|---|
| claim | Claim name of the external profile | string Optional |
| prefix | Prefix for the claim external profile If this is specified prefixPolicy will be set to “Prefix” by default | string Optional |
OsDiskProfile_DiskStorageAccountType
Used by: OsDiskProfile.
| Value | Description |
|---|---|
| “Premium_LRS” | |
| “StandardSSD_LRS” | |
| “Standard_LRS” |
OsDiskProfile_DiskStorageAccountType_STATUS
Used by: OsDiskProfile_STATUS.
| Value | Description |
|---|---|
| “Premium_LRS” | |
| “StandardSSD_LRS” | |
| “Standard_LRS” |
OsDiskProfile_DiskType
Used by: OsDiskProfile.
| Value | Description |
|---|---|
| “Ephemeral” | |
| “Managed” |
OsDiskProfile_DiskType_STATUS
Used by: OsDiskProfile_STATUS.
| Value | Description |
|---|---|
| “Ephemeral” | |
| “Managed” |
StatusType_STATUS
Representation of the possible values of a condition status.
Used by: Condition_STATUS.
| Value | Description |
|---|---|
| “False” | |
| “True” | |
| “Unknown” |
TokenClaimValidationRule_Type
Used by: TokenClaimValidationRule.
| Value | Description |
|---|---|
| “RequiredClaim” |
TokenClaimValidationRule_Type_STATUS
Used by: TokenClaimValidationRule_STATUS.
| Value | Description |
|---|---|
| “RequiredClaim” |
TokenRequiredClaim
Token required claim validation rule.
Used by: TokenClaimValidationRule.
| Property | Description | Type |
|---|---|---|
| claim | Claim name for the validation profile claim is a required field that configures the name of the required claim. | string Required |
| requiredValue | Required value requiredValue is a required field that configures the value that claim must have when taken from the incoming JWT claims. If the value in the JWT claims does not match, the token will be rejected for authentication. |
string Required |
TokenRequiredClaim_STATUS
Token required claim validation rule.
Used by: TokenClaimValidationRule_STATUS.
| Property | Description | Type |
|---|---|---|
| claim | Claim name for the validation profile claim is a required field that configures the name of the required claim. | string Optional |
| requiredValue | Required value requiredValue is a required field that configures the value that claim must have when taken from the incoming JWT claims. If the value in the JWT claims does not match, the token will be rejected for authentication. |
string Optional |
UserAssignedIdentitiesProfile
Represents the information related to Azure User-Assigned managed identities needed to perform Operators authentication based on Azure User-Assigned Managed Identities
Used by: OperatorsAuthenticationProfile.
| Property | Description | Type |
|---|---|---|
| controlPlaneOperatorsReferences | The set of Azure User-Assigned Managed Identities leveraged for the Control Plane operators of the cluster. The set of required managed identities is dependent on the Cluster’s OpenShift version. | map[string]genruntime.ResourceReference Required |
| dataPlaneOperatorsReferences | The set of Azure User-Assigned Managed Identities leveraged for the Data Plane operators of the cluster. The set of required managed identities is dependent on the Cluster’s OpenShift version. | map[string]genruntime.ResourceReference Required |
| serviceManagedIdentityReference | Represents the information associated to an Azure User-Assigned Managed Identity whose purpose is to perform service level actions. | genruntime.ResourceReference Required |
UserAssignedIdentitiesProfile_STATUS
Represents the information related to Azure User-Assigned managed identities needed to perform Operators authentication based on Azure User-Assigned Managed Identities
Used by: OperatorsAuthenticationProfile_STATUS.
| Property | Description | Type |
|---|---|---|
| controlPlaneOperators | The set of Azure User-Assigned Managed Identities leveraged for the Control Plane operators of the cluster. The set of required managed identities is dependent on the Cluster’s OpenShift version. | map[string]string Optional |
| dataPlaneOperators | The set of Azure User-Assigned Managed Identities leveraged for the Data Plane operators of the cluster. The set of required managed identities is dependent on the Cluster’s OpenShift version. | map[string]string Optional |
| serviceManagedIdentity | Represents the information associated to an Azure User-Assigned Managed Identity whose purpose is to perform service level actions. | string Optional |
UsernameClaimProfile
External Auth claim profile This configures how the username of a cluster identity should be constructed from the claims in a JWT token issued by the identity provider.
Used by: TokenClaimMappingsProfile.
| Property | Description | Type |
|---|---|---|
| claim | Claim name of the external profile | string Required |
| prefix | Prefix for the claim external profile Must be set when the prefixPolicy field is set to Prefix and must be unset otherwise. |
string Optional |
| prefixPolicy | Prefix policy is an optional field that configures how a prefix should be applied to the value of the JWT claim specified in the claim field. Allowed values are Prefix, NoPrefix, and None. If not specified, the default policy is None. When set to Prefix, the value specified in the prefix field will be prepended to the value of the JWT claim. The prefix field must be set when prefixPolicy is Prefix. When set to NoPrefix, no prefix will be prepended to the value of the JWT claim. When set to None, this means no opinion and the platform is left to choose any prefixes that are applied which is subject to change over time. Currently, the platform prepends {issuerURL}# to the value of the JWT claim when the claim is not email. As an example, consider the following scenario: prefix is unset, issuerURL is set to https://myoidc.tld, the JWT claims include “username”:“userA” and “email”:“userA |
UsernameClaimPrefixPolicy Optional |
UsernameClaimProfile_STATUS
External Auth claim profile This configures how the username of a cluster identity should be constructed from the claims in a JWT token issued by the identity provider.
Used by: TokenClaimMappingsProfile_STATUS.
| Property | Description | Type |
|---|---|---|
| claim | Claim name of the external profile | string Optional |
| prefix | Prefix for the claim external profile Must be set when the prefixPolicy field is set to Prefix and must be unset otherwise. |
string Optional |
| prefixPolicy | Prefix policy is an optional field that configures how a prefix should be applied to the value of the JWT claim specified in the claim field. Allowed values are Prefix, NoPrefix, and None. If not specified, the default policy is None. When set to Prefix, the value specified in the prefix field will be prepended to the value of the JWT claim. The prefix field must be set when prefixPolicy is Prefix. When set to NoPrefix, no prefix will be prepended to the value of the JWT claim. When set to None, this means no opinion and the platform is left to choose any prefixes that are applied which is subject to change over time. Currently, the platform prepends {issuerURL}# to the value of the JWT claim when the claim is not email. As an example, consider the following scenario: prefix is unset, issuerURL is set to https://myoidc.tld, the JWT claims include “username”:“userA” and “email”:“userA |
UsernameClaimPrefixPolicy_STATUS Optional |
CustomerManagedEncryptionProfile_EncryptionType
Used by: CustomerManagedEncryptionProfile.
| Value | Description |
|---|---|
| “KMS” |
CustomerManagedEncryptionProfile_EncryptionType_STATUS
Used by: CustomerManagedEncryptionProfile_STATUS.
| Value | Description |
|---|---|
| “KMS” |
KmsEncryptionProfile
Configure etcd encryption Key Management Service (KMS) key. Your Microsoft Entra application used to create the cluster must be authorized to access this keyvault, e.g using the AzureCLI: az keyvault set-policy -n $KEYVAULT_NAME --key-permissions decrypt encrypt --spn (YOUR APPLICATION CLIENT ID)
Used by: CustomerManagedEncryptionProfile.
| Property | Description | Type |
|---|---|---|
| activeKey | The details of the active key. | KmsKey Required |
| vaultName | vaultName is the name of the keyvault that contains the secret. | string Required |
| visibility | visibility of the keyvault that contains the secret. | KeyVaultVisibility Required |
KmsEncryptionProfile_STATUS
Configure etcd encryption Key Management Service (KMS) key. Your Microsoft Entra application used to create the cluster must be authorized to access this keyvault, e.g using the AzureCLI: az keyvault set-policy -n $KEYVAULT_NAME --key-permissions decrypt encrypt --spn (YOUR APPLICATION CLIENT ID)
Used by: CustomerManagedEncryptionProfile_STATUS.
| Property | Description | Type |
|---|---|---|
| activeKey | The details of the active key. | KmsKey_STATUS Optional |
| vaultName | vaultName is the name of the keyvault that contains the secret. | string Optional |
| visibility | visibility of the keyvault that contains the secret. | KeyVaultVisibility_STATUS Optional |
UsernameClaimPrefixPolicy
UsernameClaimPrefixPolicy configures whether to add a prefix to a JWT claim.
Used by: UsernameClaimProfile.
| Value | Description |
|---|---|
| “NoPrefix” | |
| “None” | |
| “Prefix” |
UsernameClaimPrefixPolicy_STATUS
UsernameClaimPrefixPolicy configures whether to add a prefix to a JWT claim.
Used by: UsernameClaimProfile_STATUS.
| Value | Description |
|---|---|
| “NoPrefix” | |
| “None” | |
| “Prefix” |
KeyVaultVisibility
The internet visibility of a keyvault resource
Used by: KmsEncryptionProfile.
| Value | Description |
|---|---|
| “Private” | |
| “Public” |
KeyVaultVisibility_STATUS
The internet visibility of a keyvault resource
Used by: KmsEncryptionProfile_STATUS.
| Value | Description |
|---|---|
| “Private” | |
| “Public” |
KmsKey
A representation of a KeyVault Secret.
Used by: KmsEncryptionProfile.
| Property | Description | Type |
|---|---|---|
| name | name is the name of the keyvault key used for encryption/decryption. | string Required |
| version | version contains the version of the key to use. | string Required |
KmsKey_STATUS
A representation of a KeyVault Secret.
Used by: KmsEncryptionProfile_STATUS.
| Property | Description | Type |
|---|---|---|
| name | name is the name of the keyvault key used for encryption/decryption. | string Optional |
| version | version contains the version of the key to use. | string Optional |